Lab B3: Avi WAF Policy for a Public-Facing Web App
Objectives
- Deploy Avi WAF in front of a web app and tune rules for false positives.
Prerequisites
VCF lab environment deployed and operational
Lab Environment
Standard VCF lab environment for Avi Load Balancer 30.x Specialist
Tasks
Task 1 Lab B3: Avi WAF Policy for a Public-Facing Web App
Deploy Avi WAF in front of a web app and tune rules for false positives.
Step 1
Enable WAF policy on an existing Avi VS using OWASP CRS 3.x profile.
Step 2
Run OWASP ZAP against the VS and observe WAF signatures hitting.
Step 3
Tune exceptions: whitelist benign CSRF-token patterns, disable noisy rule.
Step 4
Enable learning mode, collect 24h of traffic, promote learnings to policy.
Step 5
Validate in logs that attack traffic is blocked while legitimate requests pass.
Validation Gate
Check: Verify lab completion
Expected: Lab exercise completed successfully
Common Errors
WAF policy in detection mode producing false positives
Fix: Start WAF in detection mode (log only) for 2-4 weeks to baseline legitimate traffic and identify false positives. Common false positives: REST API calls triggering SQL injection rules, file upload endpoints triggering file inclusion rules. Create exception rules for known-good traffic patterns before switching to enforcement mode.
WAF blocking legitimate application functionality
Fix: After enabling enforcement mode, monitor application functionality and WAF logs simultaneously. A WAF rule blocking a legitimate POST request may break form submissions. Use Avi WAF learning mode to automatically suggest exceptions based on observed traffic patterns.
Not configuring WAF for the specific application's attack surface
Fix: Default WAF rule sets (CRS 3.x) are generic. A public-facing web app needs different rules than an internal API. Customize: disable rules irrelevant to the app's technology stack (e.g., PHP rules for a Java app), tune thresholds for application-specific parameters.
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
WAF design demonstrates application security architecture. VCDX panelists test whether you understand the detection → tuning → enforcement lifecycle and how you minimize false positives.
⚠ Known Pitfalls (from Community KB)
Enabling WAF enforcement without a detection-mode learning period — legitimate traffic gets blocked.
Using default WAF rules without customization — excessive false positives erode operational trust.